ADS Zone.Identifier Deleted By Uncommon Application
Description
Detects the deletion of the "Zone.Identifier" ADS by an uncommon process. Attackers can leverage this in order to bypass security restrictions that make use of the ADS such as Microsoft Office apps.
Query · sigma
selection: TargetFilename|endswith: :Zone.Identifier filter_main_generic: Image: - C:\Program Files\PowerShell\7-preview\pwsh.exe - C:\Program Files\PowerShell\7\pwsh.exe - C:\Windows\explorer.exe - C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe - C:\Windows\SysWOW64\explorer.exe - C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe filter_optional_browsers_chrome: Image: - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe - C:\Program Files\Google\Chrome\Application\chrome.exe filter_optional_browsers_firefox: Image: - C:\Program Files (x86)\Mozilla Firefox\firefox.exe - C:\Program Files\Mozilla Firefox\firefox.exe filter_optional_browsers_msedge: Image: - C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe - C:\Program Files\Microsoft\Edge\Application\msedge.exe condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
Known false positives
- Other third party applications not listed.